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Amendments to the Specification: 

Please amend the paragraph starting on page 1, line 5 as 

follows : c 

This application claims the benefit of U.S. provisional 
applications 60/138, 849, 60/138, 850, 60/139, 033, 60/139, 034 
60/139, 03 5, 60/139, 036, 60/13 9, 038, 60/139, 042, 60/139, 043, 
60/139, 044, 60/139, 047, 60/13 9, 048, 60/139, 049, 60/139, 052, 
60/139,053, all filed on June 10, 1999, and U.S. provisional 
application 60/139,076, filed on June 11, 1999, the contents of 
all of which are incorporated herein by reference. This 
application also contains subject matter that is related to the 
subject matter disclosed in U.S. Patent Application Nos. 
09/592,443, 09/591,802, 09/592,165, 09/591,801, 09/592,163, 
09/592,079, and 09/592,083, all filed on June 12, 2002. 

Please amend the paragraph starting on page j!l , line 8 as 

follows : _ ; -s: 

FIG. 7 is a screen illustration of an exemplary global 
monitor user interface 402 presenting various types of health 
^[y and status information. Such information may relate to the 
health of the device, such as system load 712 and network usage 
information 714. The information may also relate to current 
alarms 716 on the device including alarm name, type, 
description, and the like. The information may further relate 
to current VPN connections [^] 717 including connection type, 
source/destination, duration, and VPN traffic volume. 
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Please amend the paragraph starting on page 4j0t, line 2o as 

follows : . - 

In addition to the above, each log entry includes an in- 
bytes field 834 indicative of the number of bytes the 

^7 policy enforcer received as a result of the activity, and an 
L/\ out-bytes field [-&S-4] 836 indicative of the number of bytes 
transferred from the policy enforcer. Furthermore, a duration 
field [-8-3-6-] 838 indicates the duration (e.g. in seconds) of the 
activity . 

^ 

mi . z a 

Please amend the paragraph starting on page Jiff, line as 
follows : 

In step 43 6, the policy server 122 checks whether the 
updates have been successful. In this regard, the policy server 
122 waits to receive an acknowledgment from the policy enforcer 
that the updates have been successfully completed. Upon a 
positive response from the policy enforcer, the policy server 
122 deletes the apply attribute 270e for the policy enforcer's 
log DN 270e in step 438 . Otherwise, if the update was not 
successful (e.g. because the policy enforcer was down), the 
apply log is re-sent the next time another apply function is 
invoked. Alternatively, the failed policy enforcer transmits a 
request to the policy server 122 of the log of non-applied 
changes when it rejoins the network (e.g. by rebooting). 

Please amend the paragraph starting on page , line as 
follows : 
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FIG. 3 0 is an exemplary flow diagram of updating the 
primary and backup units when the primary unit is not 
functional. In step 97 8, the primary unit becomes 

nonfunctional, and in step 980, the network administrator 
f\ sends/ transmits an upgrade directly to the backup unit instead 
of the primary unit. In step 982, the backup unit updates 
itself with the information received from the management station 
and waits for the primary unit to become functional. Once the 
primary unit becomes functional in step 984 , the update is 
automatically sent /transmitted to the primary unit for upgrading 
in step 986. The primary unit then updates itself in step 988. 
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